Skip to content

Fluxuri (diagrame de secvență)

1. Ingest REST (cu idempotență + integritate + forward)

Section titled “1. Ingest REST (cu idempotență + integritate + forward)”
sequenceDiagram
autonumber
participant SaaS as Sistem SaaS
participant Ctrl as AuditEventController
participant Sec as SecurityConfig/TenantContext
participant Svc as AuditEventService
participant Idem as IdempotencyStore
participant Integ as IntegrityService
participant Repo as JpaAuditEventRepository
participant DB as PostgreSQL
participant Fwd as ForwardOutboxService
SaaS->>Ctrl: POST /api/v1/app/audit-events\n(JWT, Idempotency-Key)
Ctrl->>Sec: verifică scope audit:write + claim tenant
alt neautorizat
Sec-->>SaaS: 401 / 403
else autorizat
Ctrl->>Svc: ingest(req, REST)
Svc->>Sec: tenant guard (claim == payload.tenantId)
Svc->>Idem: known(Idempotency-Key)?
alt duplicat
Idem-->>Svc: id existent
Svc-->>Ctrl: înregistrare existentă
else nou
Svc->>Integ: computeEntryHash(prevHash, event)
Integ-->>Svc: entryHash
Svc->>Repo: save(event)
Repo->>DB: INSERT audit_event (JSONB)
Svc->>Fwd: enqueue(strategy)
end
Svc-->>Ctrl: AuditEventResponse
Ctrl-->>SaaS: 201 + Location + entryHash
Fwd-)Fwd: dispatch async (vezi flux 4)
end
sequenceDiagram
autonumber
participant Prod as Producător
participant MQ as RabbitMQ (audit.events)
participant Cons as AuditEventAmqpConsumer
participant Svc as AuditEventService
participant DB as PostgreSQL
participant DLX as audit.ingest.dlx
Prod->>MQ: publish mesaj (JSON)
MQ->>Cons: deliver (coada audit.ingest)
Cons->>Svc: ingest(req, AMQP)
alt valid
Svc->>DB: persistă (hash + JSONB)
Cons-->>MQ: ack
else invalid / eroare nerecuperabilă
Cons-->>MQ: reject (no requeue)
MQ->>DLX: rutează în dead-letter
Note over DLX: fără pierdere; alertă + replay
end

3. Verificare integritate (tamper-evident)

Section titled “3. Verificare integritate (tamper-evident)”
sequenceDiagram
autonumber
participant Aud as Auditor/Operator
participant Ctrl as AdminAuditEventController
participant Svc as AuditEventService
participant Repo as JpaAuditEventRepository
participant Integ as IntegrityService
Aud->>Ctrl: GET /api/v1/admin/audit-events/integrity\n(scope audit:admin)
Ctrl->>Svc: verifyChain(tenant, from, to, objectType)
Svc->>Repo: ia evenimentele partiției (tenant, object_type) ordonate
Repo-->>Svc: listă
loop pentru fiecare eveniment
Svc->>Integ: recalculează entryHash(prevHash, event)
Integ-->>Svc: hash recalculat
Note over Svc: dacă hash recalculat ≠ entry_hash stocat → chain break
end
Svc-->>Ctrl: {entriesChecked, chainBreaks[], lastVerifiedAt}
Ctrl-->>Aud: 200 raport integritate
sequenceDiagram
autonumber
participant Svc as AuditEventService
participant Fwd as ForwardOutboxService
participant Box as audit_forward_outbox (DB)
participant Sink as WebhookSink / MLogSink
participant Ext as SIEM/OpenSearch / MLog
Svc->>Fwd: enqueue(event, strategy LOCAL/MLOG/ALL/NONE)
Fwd->>Box: INSERT outbox (status PENDING)
Fwd-)Sink: dispatch async
alt succes
Sink->>Ext: POST payload
Ext-->>Sink: 2xx
Sink-->>Fwd: ok
Fwd->>Box: status = SENT
else eșec
Sink-->>Fwd: eroare
Fwd->>Box: status = ERROR (attempts++, backoff)
end
Note over Fwd,Box: Replay manual
participant Op as Operator
Op->>Fwd: POST /api/v1/admin/audit-events/forward/replay
Fwd->>Box: ia status=ERROR
Fwd-)Sink: re-trimite → SENT

🟡 MLogSink trimite azi doar payload-ul modelat (shaping testat); semnarea JOSE + mTLS și schema canonică MLog rămân de finalizat.